CWE-1236

Improper Neutralization of Formula Elements in a CSV File

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

292 vulnerabilities with CWE-1236
CVE-2023-5527 HIGH
Business Directory Plugin <6.4.3 - Code Injection
CVSS 7.4
CVE-2023-5424 MEDIUM
WS Form LITE <1.9.217 - Code Injection
CVSS 4.7
CVE-2023-48709 HIGH
iTop - CSV Formula Injection in Data Export
CVSS 8.0
CVE-2023-35899 HIGH
IBM Cloud Pak for Automation <22.0.2 - Code Injection
CVSS 7.0
CVE-2023-47534 CRITICAL
Fortinet FortiClientEMS <7.2.2-6.0.8 - Code Injection
CVSS 9.6
CVE-2023-45597 MEDIUM
AiLux imx6 <imx6_1.0.7-2 - Info Disclosure
CVSS 5.9
CVE-2023-47022 MEDIUM
NCR Terminal Handler <1.5.1 - Info Disclosure
CVSS 6.5
CVE-2023-31295 HIGH
Sesami CPTO <6.3.8.6 - Info Disclosure
CVSS 7.5
CVE-2023-31296 MEDIUM
Sesami CPTO <6.3.8.6 - Info Disclosure
CVSS 5.3
CVE-2023-31294 HIGH
Sesami CPTO <6.3.8.6 - Info Disclosure
CVSS 7.5
CVE-2023-50448 MEDIUM
ActiveAdmin <2.12.0 - Info Disclosure
CVSS 6.5
CVE-2023-51763 CRITICAL
ActiveAdmin <3.2.0 - Code Injection
CVSS 9.8
CVE-2023-48207 HIGH
Availability Booking Calendar 5.0 - Code Injection
CVSS 8.8
CVE-2023-42004 HIGH
IBM Security Guardium <11.6 - Code Injection
CVSS 8.0
CVE-2023-48029 HIGH
corebos < 8.0 - CSV Injection via User Management Export
CVSS 8.0
CVE-2023-41798 MEDIUM
wpWax Directorist - Improper Neutralization of Formula Elements
CVSS 5.1
CVE-2023-36527 MEDIUM
BestWebSoft Post to CSV <1.4.0 - Info Disclosure
CVSS 4.7
CVE-2023-25983 HIGH
WPOmnia KB Support <1.5.84 - Info Disclosure
CVSS 8.8
CVE-2023-23796 MEDIUM
Muneeb Form Builder <1.9.9.0 - Info Disclosure
CVSS 4.7
CVE-2023-23678 MEDIUM
WPEkaClub WP Cookie Consent <2.2.5 - Info Disclosure
CVSS 4.0
CVE-2023-22719 MEDIUM
GiveWP < 2.25.1 - CSV Injection
CVSS 4.7
CVE-2023-43071 MEDIUM
Dell SmartFabric Storage Software <1.4 - XSS
CVSS 4.4
CVE-2023-22877 HIGH
IBM InfoSphere Information Server 11.7 - Code Injection
CVSS 7.0
CVE-2023-38843 HIGH
Atlos 1.0 - Authenticated Remote Code Execution via Incident Description Field
CVSS 8.0
CVE-2023-4006 CRITICAL
thorsten/phpmyfaq <3.1.16 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 292